Summary of the judgement
On 18 March 2026, the Court of Rome annulled in its entirety order No. 755 issued by the Italian Data Protection Authority on 2 November 2024. However, the Court did not examine the substance of the alleged infringements, resolving the matter entirely on a preliminary and overriding issue: jurisdiction. A procedural defeat, one might say; yet, in terms of practical consequences, it amounts to a defeat on the merits.
The contested order: what the Data Protection Authority objected to
The Data Protection Authority alleged that OpenAI had breached Article 33 of the GDPR for failing to notify the data breach of 20 March 2023: of Articles 5(2) and 6 of the GDPR for the lack of a legal basis for the training of its models; of Articles 5(1)(a), 12 and 13 of the GDPR for shortcomings in the privacy policy; of Articles 24 and 25(1) of the GDPR for failing to put in place age verification systems; and of Article 83(5)(e) of the GDPR for failing to launch the communication campaign that had previously been ordered. The fine amounted to EUR 15 million, accompanied by a six-month institutional communication campaign across all the main Italian media outlets (radio, television, newspapers and the internet).
OpenAI challenged the order, setting out ten grounds of appeal. The Court considered only the first of these, ruling that it was well-founded and that it encompassed all the others.
The crux of the matter: who was authorised to impose the penalty?
OpenAI complained that the Data Protection Authority lacked the competence to investigate cross-border infringements and impose the resulting sanctions, as Articles 55 and 56 of the GDPR provide for the so-called “one-stop-shop” mechanism, under which the only supervisory authority “competent to act” in relation to “cross-border processing” is that “of the main establishment or of the single establishment of the controller”, in its capacity as “lead supervisory authority”.
The change in circumstances had occurred in the course of the proceedings: OpenAI set up its Irish subsidiary on 24 March 2023 and received, on 15 February 2024, formal notification from the Irish Data Protection Commission recognising OpenAI Ireland as an EU establishment for GDPR purposes. However, the penalty decision was not issued until November 2024, nine months later.
The Data Protection Authority’s argument — and its legal limitations
It must be acknowledged that the Data Protection Authority’s position was not without its own internal logic. The defendant administration replied that the penalty decision concerned infringements committed prior to 15 February 2024, taking the view that the applicable legislation ratione temporis was that in force at the time the infringement was committed, with the consequence that the one-stop-shop mechanism did not apply to infringements committed and finalised before that date. In line with such approach, the Data Protection Authority in fact partially complied with the cooperative mechanism: it forwarded to the lead authority in Ireland the documents relating to ongoing and continuing infringements, in accordance — according to its interpretation — with the principle of “tempus regit actum” referred to in Article 11 of the Preliminary Provisions.
However, the Court did not agree with this interpretation, considering that the argument was based on an erroneous reading of Opinion No. 8 of 9 July 2019 of the EDPB — a soft-law instrument adopted pursuant to Article 64 of the GDPR at the request of the French and Swedish authorities, which does not constitute a primary source of EU law but contributes to defining the rules applicable to the allocation of competences among national supervisory authorities, serving as an authoritative interpretative guide for courts and administrative authorities to ensure the uniform application of the Regulation throughout the Union.
How the Court interpreted the EDPB Opinion
The crux of the decision lies in the interpretation of Article 4.3.2 of the EDPB Opinion, which specifically governs the creation of a main establishment whilst proceedings are ongoing.
The EDPB has clarified that “the creation of a main or single establishment or its relocation from a third country to the EEA” whilst proceedings are ongoing ”will allow the controller to benefit from the one-stop-shop, with the consequence that every pending proceeding will be transferred to the supervisory authority of the State in which the main establishment is located” and that “such supervisory authority will become the lead supervisory authority”.
The Data Protection Authority’s defence regarding the continued applicability of the one-stop-shop mechanism solely in relation to ongoing or continued infringements was found to lack a legal basis, stemming from an erroneous interpretation of paragraph 16 of the Opinion, which refers the issues addressed “mainly” to infringements of an ongoing or continued nature. The Court observed that the very use of the adverb “mainly” serves to rule out the possibility that the EDPB intended to limit the issues covered by the Opinion solely to ongoing infringements; rather, it sought to indicate the types of infringements in which such issues arise most frequently.
The underlying principle is even more significant: making the determination of the competent authority dependent on the nature of the alleged infringement would not only cause the uncertainty that the EU legislation aims to avoid, but also a reversal of the logical legal order in which issues are examined, making the resolution of a preliminary question such as jurisdiction dependent on the outcome of the examination of a question of substance.
The “tempus regit actum” argument — rejected
The Data Protection Authority also invoked the legal principle of “tempus regit actum” to argue that the applicable legislation was that in force at the time the infringements were committed. The Court considered this argument to be irrelevant: in the present case, what is at issue is not a change in the applicable legislation during the course of the proceedings, but rather the change in certain factual circumstances — the creation of a single establishment by the data controller within the territory of the Union — the consequences of which are taken into account and governed by the EDPB Opinion. It is not, therefore, a matter of the retroactive application of the law, but of adapting jurisdiction to supervening facts, as already provided for and regulated by European law.
The exceptions that did not apply
The Court also examined whether any of the exceptional circumstances applied in which jurisdiction reverts to the national authority concerned. In this regard, Article 56(2) of the GDPR — according to which each supervisory authority is competent to handle complaints that relate solely to an establishment in its Member State or that have a substantial impact on data subjects solely within its Member State — and Article 66, which, by way of derogation from Article 60, grants each supervisory authority the power to adopt provisional measures where it considers that urgent action is required to protect the rights and freedoms of data subjects. In addition to these cases, there is the case where the lead supervisory authority, although seised of the matter, decides not to handle the case (see, to that effect, CJEU, C-645/19, Facebook Ireland and Others). However, none of these exceptional circumstances was found to exist in the present case.
The case law of the Court of Cassation
The Supreme Court had already clarified that “the national data protection authority is entitled to impose sanctions where it appears that the processing was carried out by an Italian company with full and direct decision-making autonomy with regard to personal data” (order, First Division, No. 27189 of 22 September 2023) and that “the Italian Data Protection Authority has the power to issue the measures falling within its remit against a foreign entity, even if it is established outside the Union, which operates outside the national territory, provided that it carries out, through a permanent establishment on Italian territory, an actual and genuine activity in the context of which the processing takes place” (judgement of First Division, No. 3952 of 2022). In both rulings, the prerequisite for recognising the Italian Data Protection Authority’s power to impose sanctions is identified as the presence on Italian territory of a company or a permanent establishment: circumstances which do not exist in the present case.
The Court’s decision therefore forms part of a consistent line of case law.
The data point worth more than a thousand arguments
Other supervisory authorities, although “concerned” at the time proceedings were initiated in relation to the same infringements committed by the applicant company, subsequently declined to exercise their jurisdiction in favour of the Irish supervisory authority, which was deemed to be the lead authority from 15 February 2024, and forwarded all the investigative files to it. The Italian Data Protection Authority was left on its own. The Court held that it was in the wrong — whilst acknowledging, in the allocation of legal costs, the genuine novelty and complexity of the issues addressed.
The operative part
The creation of the data controller’s single establishment pending the administrative proceedings — even though these had been lawfully initiated in January 2024 — should have
immediately resulted in its transfer to the supervisory authority of the State in which the main establishment is located — in this case, the Irish authority — and the initiation of the cooperation mechanism set out in Articles 60 and 61 of the Regulation. In upholding the appeal, the Court annulled order No. 755 of the Data Protection Authority dated 2 November 2024. The costs of the proceedings have been shared between the parties, given the novelty of the issues involved.
The merits of the case remain open — and this is what matters
The judgement does not amount to a ruling on the merits. The infringements originally alleged by the Italian Data Protection Authority — legal basis for training the models, transparency, age verification, data breach and failure to implement previously-imposed corrective measures — remain intact and will presumably be addressed by the Irish DPC under the cooperative mechanism set out in Articles 60 and 61 of the GDPR. The case file is not extinguished; it merely changes hands.
Implications: a lesson that extends far beyond OpenAI
The ruling by the Court of Rome has implications that extend far beyond the parties to the case. The legal issues identified — legal basis for training AI models, transparency obligations towards users, age verification, and the handling of data breaches — are structural issues affecting any provider of artificial intelligence systems offering their services to European users, regardless of what emerges from the new Digital Omnibus legislative and regulatory framework.
For non-EU AI providers currently operating on the European market without a formally recognised establishment, the picture that emerges from the judgement is clear:
For AI system providers with an established presence in Europe, however, the ruling serves as a reminder that the choice of country of establishment — and the speed with which formal recognition is obtained from the local regulatory authority — is a decision with regulatory implications of the utmost importance: not a corporate detail, but a strategic lever for risk management.
In conclusion: whilst the Court of Rome has (for now) brought the Italian chapter of the OpenAI case to a close, the issues that fuelled the preliminary investigation remain unresolved and highly topical. Anyone who develops or distributes artificial intelligence systems aimed at the European market — from any country in the world — will sooner or later have to grapple with them.